{"id":34696,"date":"2019-10-24T09:24:18","date_gmt":"2019-10-24T09:24:18","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/?p=34696"},"modified":"2019-10-29T08:28:49","modified_gmt":"2019-10-29T08:28:49","slug":"ciisec-warns-organisations-are-at-risk-due-to-lack-of-diversity","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2019\/10\/24\/ciisec-warns-organisations-are-at-risk-due-to-lack-of-diversity\/","title":{"rendered":"CIISec warns organisations are at risk due to lack of diversity"},"content":{"rendered":"\n<p>The IT security industry is still failing to attract workers beyond a highly limited demographic, the Chartered Institute of Information Security (CIISec) has warned. <\/p>\n\n\n\n<p>Unless it can embrace greater diversity \u2013 in gender, age, ethnicity, disabilities and experience \u2013 it will face a stagnating workforce and be unable to keep up with a rapidly expanding skills gap. <\/p>\n\n\n\n<p>According to the <a href=\"https:\/\/www.esg-global.com\/blog\/the-cybersecurity-skills-shortage-is-getting-worse\">Enterprise Strategy Group<\/a>, the number of organisations reporting a problematic shortage of cybersecurity skills has increased every year since 2015. <\/p>\n\n\n\n<p>At the same time, CIISec\u2019s survey of information security professionals showed that 89% of respondents were male and 89% were over 35; meaning the profession is still very much in the hands of older men. If the diversity issue isn\u2019t addressed, then not only security, but future development of the cybersecurity industry itself, will suffer. <\/p>\n\n\n\n<p>Many organisations point to the need to develop specialist security skills as a reason for reduced diversity, as employees need the right technical background. Yet the majority of IT security professionals \u2013 65% \u2013 still believe that the best way to develop security skills is to learn on the job. <\/p>\n\n\n\n<p>At the same time, many individuals will have already developed the skills needed in security in other careers, from attention to detail and identifying unusual patterns of behaviour, to the communication skills needed to drive security awareness and behavioural change in others.<\/p>\n\n\n\n<p>\u201cThe expectation that security is purely a technical subject has led to a focus only on very specific individuals to fulfil roles,\u201d said Amanda Finch, CEO of the Chartered Institute of Information Security. <\/p>\n\n\n\n<p>\u201cEven if we weren\u2019t in the middle of a skills crisis increased diversity should be a priority, but the present situation makes it critical. Expanding the industry\u2019s horizons isn\u2019t only essential to make sure the industry has the skills it needs. <\/p>\n\n\n\n<p>&#8220;It will give a whole range of individuals the opportunity to thrive in a new career and in the long term protect the industry from stagnation by introducing more varied backgrounds.\u201d<\/p>\n\n\n\n<p>As a broad industry, security has a position for every background and multiple opportunities to apply already-existing skills. For instance, a librarian may be particularly adept at, and find satisfaction in, recalling and connecting information to ensure everything is in its correct place \u2013 essential in spotting evidence of a security breach. <\/p>\n\n\n\n<p>Other examples of transferable skills include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Tracking and managing multiple actions at once \u2013 parent returning to work<\/li><li>Leading teams in stressful conditions \u2013 armed forces<\/li><li>Demonstrating and explaining best practice clearly \u2013 teacher<\/li><li>Teamwork and collaboration under pressure \u2013 hospitality staff<\/li><li>Following best practice consistently while still being able to adapt \u2013 driver<\/li><\/ul>\n\n\n\n<p>As well as expanding its own horizons, the industry also needs to make a more diverse audience aware of the benefits a career in security can provide and encourage them to switch careers or begin a new path. The opportunities are clear. A total of 86% of information security professionals say the industry will grow over the next three years and 13% say it will &#8216;boom&#8217;. <\/p>\n\n\n\n<p>\u201cIf the industry starts to attract a more diverse range of people while spreading awareness of the opportunity available, we could be well on the way to truly modernising the industry,\u201d continued Amanda Finch. <\/p>\n\n\n\n<p>\u201cKey to all this will be both organisations and individuals having a framework that can show exactly what skills are necessary to fulfil what roles. This will not only help hire the right people, it will also mean that it the routes to progress through an individual\u2019s career are clearly marked, ensuring that individuals who enthusiastically join the industry don\u2019t over time become jaded or burn out due to a lack of opportunity.\u201d<\/p>\n\n\n\n<p>Nicola Whiting, Chief Strategy Officer, Titania, said: &#8220;Our industry only has two key missions: creating new, innovative and beneficial solutions, and ensuring they are resilient to attack. Organisations that haven\u2019t invested in diversity will have a tendency towards \u2018group think\u2019 \u2013 known to result in unchallenged and poor-quality decision making, with all its attendant risks. <\/p>\n\n\n\n<p>&#8220;Most people would also agree that \u2018to defeat an attacker, we must learn to think like an attacker\u2019: and attackers are a diverse bunch. Therefore, for both innovation and defence, it\u2019s essential that organisations look at diversity as a key metric for success.\u201d<\/p>\n\n\n\n<p>John Amer, Security Architect, BT, added:<strong> <\/strong>\u201cAs the security industry continue to evolve, it\u2019s absolutely critical that we attract people from different areas. A diverse workforce helps to bring a wide range of skills and perspectives, which is essential to address the range of opportunities and threats that an increasingly digital world provides. <\/p>\n\n\n\n<p>&#8220;By actively raising awareness of careers in cybersecurity and the types of roles and skills required, we can attract people from all backgrounds, age groups and experiences. This will be crucial to tackle the cyberskills gap and to enable organisations to meet the challenges of today and tomorrow.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The IT security industry is still failing to attract workers beyond a highly limited demographic, the Chartered Institute of Information Security (CIISec) has warned. Unless it can embrace greater diversity \u2013 in gender, age, ethnicity, disabilities and experience \u2013 it will face a stagnating workforce and be unable to keep up with a rapidly expanding [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":34803,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,6617,93],"tags":[1098,13687,564,8429,13688,13689],"class_list":["post-34696","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-research","category-top-stories","tag-bt","tag-chartered-institute-of-information-security","tag-cybersecurity","tag-cyberskills","tag-john-amer","tag-security-architect"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/34696","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=34696"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/34696\/revisions"}],"predecessor-version":[{"id":34698,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/34696\/revisions\/34698"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/34803"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=34696"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=34696"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=34696"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}